Repository navigation
fix(seismic): certbot no longer gates consensus, renewal survives reboot - #80
Merged
samlaf merged 1 commit intoOct 8, 2026
Conversation
reth and summit had After=/Requires=nginx-ssl-setup.service, so a failed Let's Encrypt issuance kept the execution and consensus clients down, although neither needs public HTTPS. Drop that edge; tdx-init ordering is still carried by persistent-luks-setup. certbot-renew.timer was enabled at runtime by nginx-ssl-setup, which the tmpfs rootfs forgets on reboot, and its WantedBy=timers.target is masked by the debloat script. Enable it at build time into minimal.target.wants instead, and gate certbot-renew.service on /persistent/nginx/.certbot-done so it is skipped on nodes that never obtained a certificate. nginx-ssl-setup.service said WantedBy=multi-user.target and reached minimal.target only through the ln -sf in mkosi.postinst's enable loop. With it on minimal.target, every unit in the loop is, so systemctl enable creates each link and the ln -sf goes. The CI image-contents check now expects certbot-renew and nginx-ssl-setup, with the minimal.target.wants links of the two enabled units. Update the module readme to match. Refs: SEI-820
samlaf
deleted the
sl/sei-820-fix-certbot-gates-consensus-and-certificate-renewal-is-lost
branch
October 8, 2026 15:57
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
reth and summit had After=/Requires=nginx-ssl-setup.service, so a failed Let's Encrypt issuance kept the execution and consensus clients down, although neither needs public HTTPS. Drop that edge; tdx-init ordering is still carried by persistent-luks-setup.
certbot-renew.timer was enabled at runtime by nginx-ssl-setup, which the tmpfs rootfs forgets on reboot, and its WantedBy=timers.target is masked by the debloat script. Enable it at build time into minimal.target.wants instead, and gate certbot-renew.service on /persistent/nginx/.certbot-done so it is skipped on nodes that never obtained a certificate.
nginx-ssl-setup.service said WantedBy=multi-user.target and reached minimal.target only through the ln -sf in mkosi.postinst's enable loop. With it on minimal.target, every unit in the loop is, so systemctl enable creates each link and the ln -sf goes.
The CI image-contents check now expects certbot-renew and nginx-ssl-setup, with the minimal.target.wants links of the two enabled units. Update the module readme to match.
Fixes SEI-820